# Metricbeat 8.11.0 - system module using excessive amount of memory

**URL:** <https://discuss.elastic.co/t/metricbeat-8-11-0-system-module-using-excessive-amount-of-memory/347236>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [November 15, 2023, 3:54pm UTC](https://discuss.elastic.co/t/metricbeat-8-11-0-system-module-using-excessive-amount-of-memory/347236 "2023-11-15T15:54:31Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![twilson](https://avatars.discourse-cdn.com/v4/letter/t/2bfe46/32.png) [@twilson](https://discuss.elastic.co/u/twilson)\
**Post date:** [November 15, 2023, 3:54pm UTC](https://discuss.elastic.co/t/metricbeat-8-11-0-system-module-using-excessive-amount-of-memory/347236/1 "2023-11-15T15:54:31Z")

</div>

I'm using the system integration with the Elastic agent and have the ' Collect metrics from System instances' option enabled, with all the default datasets within that selected. With the 8.11.0 version of this integration the amount of memory the metricbeat process consumes continues to grow over time, in to the GB range.

I've narrowed this down to two specific metric sets - 'System process metrics' and 'System process\_summary metrics'. When these two metric sets are disabled the memory usage remains low and constant. The following information was pulled using 'tasklist /v'.

Memory usage after 12 hours with the two suspect metric sets disabled:

```auto
Image Name PID Session Name Session# Mem Usage 
========================= ======== ================ =========== ============ 
metricbeat.exe 10468 Services 0 122,036 K

```

Memory usage after 1 hour with the two suspect metric sets enabled:

```auto
Image Name PID Session Name Session# Mem Usage 
========================= ======== ================ =========== ============ 
metricbeat.exe 10468 Services 0 1,011,256 K

```

This is happening on all Windows machines with the 8.11.0 agent/metricbeat. During the time it took me to type this the memory usage has increased to 1,117,656 K. I've performed the tests of disabling/enabling the metrics multiple times and have reached the same results.

This is not happening with Windows machines running 8.10.4 agent/metricbeat. I've looked through the agent logs and could no nothing to indicate a problem.

---

<div class="post-metadata">

**Author:** ![catn0b0t](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/catn0b0t/32/122758_2.png) [@catn0b0t](https://discuss.elastic.co/u/catn0b0t)\
**Post date:** [November 16, 2023, 1:48pm UTC](https://discuss.elastic.co/t/metricbeat-8-11-0-system-module-using-excessive-amount-of-memory/347236/2 "2023-11-16T13:48:08Z")

</div>

Jup, we just noticed the same thing. I pulled a graph of the average Metricbeat memory usage over all our hosts and this is what that looks like. The memory consumption starts at a normaal 0.5Gb and then grows to almost 4Gb overnight.

 ![MicrosoftTeams-image](https://us1.discourse-cdn.com/elastic/original/3X/c/2/c2628538ae68044b7037fb0a5b1b50e4f2b3eb3b.png)

---

<div class="post-metadata">

**Author:** ![catn0b0t](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/catn0b0t/32/122758_2.png) [@catn0b0t](https://discuss.elastic.co/u/catn0b0t)\
**Post date:** [November 16, 2023, 3:25pm UTC](https://discuss.elastic.co/t/metricbeat-8-11-0-system-module-using-excessive-amount-of-memory/347236/3 "2023-11-16T15:25:31Z")

</div>

Additional observation. I have been playing with the "System process metrics" period and this seems to have a big impact on the speed the memory leak grows. If i lower the period to 1s, I can see the memory usage by metrics grow by the second, it just doesn't releas any of it. When I raise the period to 30sec, I still see the memory only growing, but at a much slower pace.

---

<div class="post-metadata">

**Author:** ![pikaia](https://avatars.discourse-cdn.com/v4/letter/p/48db29/32.png) [@pikaia](https://discuss.elastic.co/u/pikaia)\
**Post date:** [November 20, 2023, 3:40pm UTC](https://discuss.elastic.co/t/metricbeat-8-11-0-system-module-using-excessive-amount-of-memory/347236/4 "2023-11-20T15:40:58Z")

</div>

We are seeing the same behavior... Could this be a bug?

---

<div class="post-metadata">

**Author:** ![Frank\_Barton](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_barton/32/76687_2.png) [@Frank\_Barton](https://discuss.elastic.co/u/Frank_Barton)\
**Post date:** [November 20, 2023, 4:51pm UTC](https://discuss.elastic.co/t/metricbeat-8-11-0-system-module-using-excessive-amount-of-memory/347236/5 "2023-11-20T16:51:43Z")

</div>

There is a confirmed bug

> <https://github.com/elastic/beats/issues/37142>
>
> Hi there,
> We are using the latest version v8.11.0 of the Elastic Agent here. 
> …We recently had a crash of metricbeat with probably a memory leak, 10GB RAM usage and then crash.
> 
> metricbeat 10GB RAM Usage:
> !\[Screenshot 2023-11-17 103837\](https://github.com/elastic/beats/assets/6105075/509f458d-2efc-4ad7-b4a1-15734c3977eb)
> 
> memmory usage metricbeat time period 7 days:
> !\[Screenshot 2023-11-17 112524\](https://github.com/elastic/beats/assets/6105075/df78542c-1da4-449d-a7ae-999e6ff44aa5)
> 
> Number of proccess handels metricbeat rises to over 3 million over 7 days:
> !\[Screenshot 2023-11-17 113602\](https://github.com/elastic/beats/assets/6105075/a196efc4-f466-4c6f-8029-7c7988a9a4e7)
> 
> metricbeat crash:
> !\[Screenshot 2023-11-17 103949\](https://github.com/elastic/beats/assets/6105075/83e97bbc-f1a6-4233-ab18-384b62ddbfb8)
> 
> The system, Win2k19, was unusable for a long time. Priority 1 should be to search for the bug, as this is very risky in a productive environment.
> 
> I have a diagnostic log file from the Elastic Agent, if you are interested i can upload it.
> 
> https://github.com/elastic/beats/issues/35796

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 18, 2023, 6:51pm UTC](https://discuss.elastic.co/t/metricbeat-8-11-0-system-module-using-excessive-amount-of-memory/347236/6 "2023-12-18T18:51:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
